<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/css" media="screen" href="http://s2.wp.com/wp-content/themes/vip/newyorkobserver/stylesheets/rss.css"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Betabeat &#187; How Is Anonymous Going After The French Co. Trying To Trademark Its Logo? Let Us Count The Ways</title>
	<atom:link href="http://betabeat.com/2012/07/how-is-anonymous-going-after-french-co-trying-to-trademark-its-logo-let-us-count-the-ways/feed/" rel="self" type="application/rss+xml" />
	<link>http://betabeat.com</link>
	<description>Just another WordPress.com site</description>
	<lastBuildDate>Thu, 23 May 2013 21:03:21 +0000</lastBuildDate>
	<language></language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='betabeat.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Betabeat &#187; How Is Anonymous Going After The French Co. Trying To Trademark Its Logo? Let Us Count The Ways</title>
		<link>http://betabeat.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://betabeat.com/osd.xml" title="Betabeat" />
	<atom:link rel='hub' href='http://betabeat.com/?pushpress=hub'/>
		<item>
				
		<title>How Is Anonymous Going After The French Co. Trying To Trademark Its Logo? Let Us Count The Ways</title>

		<comments>http://betabeat.com/2012/07/how-is-anonymous-going-after-french-co-trying-to-trademark-its-logo-let-us-count-the-ways/#comments</comments>
		<pubDate>Tue, 31 Jul 2012 22:44:51 -0400</pubDate>
					<link>http://betabeat.com/2012/07/how-is-anonymous-going-after-french-co-trying-to-trademark-its-logo-let-us-count-the-ways/</link>
			<dc:creator>Steve Huff</dc:creator>
				
		<guid isPermaLink="false">http://betabeat.com/?p=56872</guid>
		<description><![CDATA[<p><div id="attachment_20900" class="wp-caption alignleft" style="width: 264px"><a href="http://nyobetabeat.files.wordpress.com/2011/11/anonymoussuit.jpg"><img class="size-medium wp-image-20900" title="anonymoussuit" src="http://nyobetabeat.files.wordpress.com/2011/11/anonymoussuit.jpg?w=254" alt="" width="254" height="300" /></a><p class="wp-caption-text">No, seriously, you should expect this.</p></div></p>
<p>Earlier <a href="http://betabeat.com/2012/07/some-genius-at-a-french-retailer-wants-to-trademark-the-anonymous-logo/" target="_blank">we learned</a> a French retailer, <a href="http://www.eflicker.fr/" target="_blank">E-Flicker</a>, has sought to register both Anonymous's well-known question-mark/empty suit logo and the activist collective's tagline, "We are anonymous. We are Legion. We do not forgive. We do not forget. Expect us."</p>
<p>Anonymous responded with the video below but in poking around <a href="http://pastebin.com/" target="_blank">Pastebin.com</a> we found a few pages intended to assist Anons in their next move against E-Flicker. One examined server vulnerabilities behind one of the company's websites and the paster's conclusion is that E-Flicker, in trying to monetize Anonymous--in the collective's words, make it "the whore of the world"--is vulnerable to at least one particular kind of hack attack:<!--more--></p>
<blockquote><p>The URL: http://www.eflicker.fr/contact.php is vulnerable to cross site request forgery. It allows the attacker to exchange the method from POST to GET when sending data to the server.</p></blockquote>
<p>"Cross site request" forgeries can, in <a href="http://www.codinghorror.com/blog/2008/09/cross-site-request-forgeries-and-you.html" target="_blank">the words of CodingHorror blogger Jeff Atwood</a>, let attackers "initiate any arbitrary action they like on a target website."</p>
<p>A deeper look at recent Pastebin posts indicates Anons--or those sympathetic to Anonymous--are digging up other vulnerabilities as well. One page purports to identify SQL injection vulnerabilities for eflicker.fr. An SQL injection can give a hacker the ability to attack databases and glean fun stuff like credit card numbers and user passwords.</p>
<p>A third Pastebin page appears to offer code meant to assist a <a href="http://blog.spiderlabs.com/2012/01/hoic-ddos-analysis-and-detection.html/" target="_blank">HOIC DDoS attack</a> on eflicker.fr and related subdomains. The High Orbit Ion Cannon is a different flavor of the Anon-beloved LOIC (Low Orbit Ion Cannon). Spiderlabs.com reported in January that HOIC makes it hard for a targeted website to determine if it is actually being DDoSed or not, using "randomization techniques" to "evade detection."</p>
<p>But a wrathful Anonymous may not stop with cross site request forgeries, SQL injections or the tried and true DDoS attack. E-Flicker head Apollinaire Auffret has already been "doxed"--his personal info including phone numbers and email addresses published for all to see--in multiple locations on Pastebin and elsewhere.</p>
<p>Mr. Auffret, it goes without saying, should have expected this.</p>
<p><span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='420' height='315' src='http://www.youtube.com/embed/yuq9bBiRELA?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span></p>
<p>via <a href="http://www.youtube.com/watch?v=yuq9bBiRELA">Anonymous: Operation AnonTrademark [english] - YouTube</a>.</p>
]]></description>
		<content:encoded><![CDATA[<p><div id="attachment_20900" class="wp-caption alignleft" style="width: 264px"><a href="http://nyobetabeat.files.wordpress.com/2011/11/anonymoussuit.jpg"><img class="size-medium wp-image-20900" title="anonymoussuit" src="http://nyobetabeat.files.wordpress.com/2011/11/anonymoussuit.jpg?w=254" alt="" width="254" height="300" /></a><p class="wp-caption-text">No, seriously, you should expect this.</p></div></p>
<p>Earlier <a href="http://betabeat.com/2012/07/some-genius-at-a-french-retailer-wants-to-trademark-the-anonymous-logo/" target="_blank">we learned</a> a French retailer, <a href="http://www.eflicker.fr/" target="_blank">E-Flicker</a>, has sought to register both Anonymous's well-known question-mark/empty suit logo and the activist collective's tagline, "We are anonymous. We are Legion. We do not forgive. We do not forget. Expect us."</p>
<p>Anonymous responded with the video below but in poking around <a href="http://pastebin.com/" target="_blank">Pastebin.com</a> we found a few pages intended to assist Anons in their next move against E-Flicker. One examined server vulnerabilities behind one of the company's websites and the paster's conclusion is that E-Flicker, in trying to monetize Anonymous--in the collective's words, make it "the whore of the world"--is vulnerable to at least one particular kind of hack attack:<!--more--></p>
<blockquote><p>The URL: http://www.eflicker.fr/contact.php is vulnerable to cross site request forgery. It allows the attacker to exchange the method from POST to GET when sending data to the server.</p></blockquote>
<p>"Cross site request" forgeries can, in <a href="http://www.codinghorror.com/blog/2008/09/cross-site-request-forgeries-and-you.html" target="_blank">the words of CodingHorror blogger Jeff Atwood</a>, let attackers "initiate any arbitrary action they like on a target website."</p>
<p>A deeper look at recent Pastebin posts indicates Anons--or those sympathetic to Anonymous--are digging up other vulnerabilities as well. One page purports to identify SQL injection vulnerabilities for eflicker.fr. An SQL injection can give a hacker the ability to attack databases and glean fun stuff like credit card numbers and user passwords.</p>
<p>A third Pastebin page appears to offer code meant to assist a <a href="http://blog.spiderlabs.com/2012/01/hoic-ddos-analysis-and-detection.html/" target="_blank">HOIC DDoS attack</a> on eflicker.fr and related subdomains. The High Orbit Ion Cannon is a different flavor of the Anon-beloved LOIC (Low Orbit Ion Cannon). Spiderlabs.com reported in January that HOIC makes it hard for a targeted website to determine if it is actually being DDoSed or not, using "randomization techniques" to "evade detection."</p>
<p>But a wrathful Anonymous may not stop with cross site request forgeries, SQL injections or the tried and true DDoS attack. E-Flicker head Apollinaire Auffret has already been "doxed"--his personal info including phone numbers and email addresses published for all to see--in multiple locations on Pastebin and elsewhere.</p>
<p>Mr. Auffret, it goes without saying, should have expected this.</p>
<p><span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='420' height='315' src='http://www.youtube.com/embed/yuq9bBiRELA?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span></p>
<p>via <a href="http://www.youtube.com/watch?v=yuq9bBiRELA">Anonymous: Operation AnonTrademark [english] - YouTube</a>.</p>
]]></content:encoded>
		<wfw:commentRss>http://betabeat.com/2012/07/how-is-anonymous-going-after-french-co-trying-to-trademark-its-logo-let-us-count-the-ways/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:thumbnail url="http://nyobetabeat.files.wordpress.com/2011/11/anonymoussuit.jpg?w=127" />
		<media:content url="http://nyobetabeat.files.wordpress.com/2011/11/anonymoussuit.jpg?w=127" medium="image">
			<media:title type="html">anonymoussuit</media:title>
		</media:content>

		<media:content url="http://1.gravatar.com/avatar/12d391316d94afeef01bd9a987c847fe?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">shuffobserver</media:title>
		</media:content>

		<media:content url="http://nyobetabeat.files.wordpress.com/2011/11/anonymoussuit.jpg?w=254" medium="image">
			<media:title type="html">anonymoussuit</media:title>
		</media:content>
	</item>
	</channel>
</rss>
